Following half a year of public consultation, the much-anticipated final rules on Regulating and Facilitating Cross-border Data Flows were published by the Cyberspace Administration of China (CAC). Taking effect on March 22, 2024, these new regulations tend to echo their initial drafts but now take a more relaxed stance on the export of personal data from China.
The same day also saw the release of the Guide to the Application for Security Assessment of Data Exports (Second Edition) and the Guide to the Filing of the Standard Contract for Personal Data Exports (Second Edition) by the CAC, informally referred to as the Second Edition Guides. This was done to accommodate the modifications that were introduced in the new regulations. This process signifies the progressive steps taken by the Chinese administrative body in easing outbound data transfers from China.
For a more detailed understanding of the development, readers can refer to the article on Law.com and a Privacy World article on the initial proposal of the draft regulation for facilitating cross-border data transfers.
These relaxed provisions and the exception to signing standard contracts are a noteworthy shift in the government’s approach towards data security assessments. The new laws are bound to affect numerous corporations and law firms operating in China who regularly deal with cross-border data transfer protocol, underscoring the need for legal professionals to remain updated about these significant regulatory changes.